Impact
Insufficient policy enforcement within Chrome DevTools permits a remote attacker who has already compromised the renderer process to serve a crafted HTML page that can escape the renderer sandbox. This vulnerability is identified by CWE-693. If the escape is successful, the attacker obtains execution at the renderer’s privileges, allowing local code execution and compromising the confidentiality, integrity, and availability of the host system.
Affected Systems
All desktop editions of Google Chrome running on Windows, macOS, or Linux are impacted when the installed version is older than 150.0.7871.47.
Risk and Exploitability
The CVSS score of 9.6 reflects a severe impact, yet the EPSS score is below 1 %, and the vulnerability does not appear in the CISA KEV catalog, suggesting limited known exploitation. The likely attack requires a pre‑existing compromise of the renderer process, after which the DevTools policy bypass via a specially crafted HTML page can trigger a sandbox escape, resulting in local code execution.
OpenCVE Enrichment
Debian DLA
Debian DSA